|
Process Viewers (Programs
running in Memory)
One of our favourite tools to detects and removes
rootkits from gmer.net. Gmer tools shows hidden processes, hidden threads,
hidden modules (.dll's), hidden services, hidden files, hidden Alternate Data
Streams, hidden registry keys, drivers hooking SSDT drivers hooking IDT drivers
hooking IRP calls inline hooks
Kernel Detective:
Yet another good tool to view process in
memory.
Kernel Detective can also Detect Hidden Processes,
Detect Hidden Threads, Detect Hidden DLLs, Detect Hidden Handles, Detect Hidden
Driver, Detect Hooked SSDT, Detect Hooked Shadow SSDT, Detect Hooked IDT, Detect
Kernel-mode code modifications and hooks. Disassemble (Read/Write)
Kernel-mode/User-mode memory. Monitor debug output on your system.
Emco - UnLock IT One-Click Unlock of Locked
Files and Locked Folders. If all other unlockers fails you can try this. Very
useful to delete files locked by Viruses. Was very much helpful while removing
files locked by MebRoot virus on one of our clients machine.
All the above tools can be found click here
|